IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2015-10-09T14:00:00

Updated: 2016-12-06T18:57:01

Reserved: 2015-07-01T00:00:00


Link: CVE-2015-5234

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2015-10-09T14:59:01.843

Modified: 2018-10-30T16:27:35.843


Link: CVE-2015-5234

JSON object: View

cve-icon Redhat Information

No data.

CWE